Application context via endpoint-aware traffic for enhanced security
Abstract
Techniques for providing application context via endpoint-aware traffic for enhanced security are disclosed. In some embodiments, a system/process/computer program product for providing application context via endpoint-aware traffic for enhanced security includes collecting process information for a process at an endpoint; injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint environment to apply a security policy based on a contextual application identifier (App-ID).
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system, comprising:
a processor configured to:
collect process information for a process at an endpoint;
inject the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and
process the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID); and
a memory coupled to the processor and configured to provide the processor with instructions.
2 . The system of claim 1 , wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service.
3 . The system of claim 1 , wherein the security platform and/or the security service monitors the endpoint-aware traffic, and wherein the security platform includes a firewall, a network gateway firewall (NGFW), and/or another network device, and wherein the security service includes a cloud-based security service.
4 . The system of claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.
5 . The system of claim 1 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name.
6 . The system of claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy.
7 . The system of claim 1 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID.
8 . The system of claim 1 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy.
9 . The system of claim 1 , wherein the processor is further configured to:
extract the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.
10 . The system of claim 1 , wherein the processor is further configured to:
extract the process information and automatically group a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on a contextual App-ID for the plurality of traffic sessions; and wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.
11 . A method, comprising:
collecting process information for a process at an endpoint; injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID).
12 . The method of claim 11 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.
13 . The method of claim 11 , wherein indicators are configured on the endpoint to collect the process information at the endpoint, and wherein the process information includes a process identifier (PID), a process parent identifier (PPID), and a process name.
14 . The method of claim 11 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy.
15 . The method of claim 11 , wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on the contextual App-ID.
16 . The method of claim 11 , wherein identification of the contextual App-ID is performed prior to a start of a new session associated with network traffic for the new session, wherein the identification of the contextual App-ID prior to the start of the new session reduces risks associated with data leakage by preventing a forwarding of any packets from the new session based on the contextual App-ID and the security policy.
17 . The method of claim 11 , further comprising:
extracting the process information and automatically grouping a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; and wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying a security policy based on a contextual App-ID for the plurality of traffic sessions.
18 . The method of claim 11 , further comprising:
extracting the process information and automatically grouping a plurality of traffic sessions sharing a common process identifier (PID) and/or a common parent process identifier (PPID) to be associated with a single application; wherein the endpoint-aware traffic is processed at the security platform and/or the security service to provide contextual information associated with the network traffic for applying the security policy based on a contextual App-ID for the plurality of traffic sessions; and wherein if any of the network traffic within the group matches one or more existing App-ID signatures for identifying an application, then each of the plurality of traffic sessions associated with the group are automatically identified as being associated with the application.
19 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
collecting process information for a process at an endpoint; injecting the process information as metadata into network traffic associated with the process to generate endpoint-aware traffic; and processing the endpoint-aware traffic at a security platform or a security service to access more comprehensive information about the endpoint to apply a security policy based on a contextual application identifier (App-ID).
20 . The computer program product of claim 19 , wherein indicators are configured on the endpoint to collect the process information at the endpoint using an agent executed on the endpoint.Join the waitlist — get patent alerts
Track US2026081893A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.